Status: July 23, 2026
1. Responsible Party
SelectCode GmbH
Oskar-vonMiller-Straße 11
82008 Unterhaching
Germany
Contact:
Email: datenschutz@meingpt.com
Telephone: +49 89 54198646
Website: https://meingpt.com
Management: Florian Baader, Reiner Conrad
Data Protection Officer:
heyData GmbH
Schützenstr. 5
10117 Berlin
Email: datenschutz@heydata.eu
Competent Supervisory Authority:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
2. Overview of Processing
This privacy policy informs you about the nature, scope and purpose of the processing of personal data when using our B2B AI platform meinGPT.
Important note for corporate customers: As an administrator, you are responsible for ensuring that data is used in accordance with data protection regulations within your organisation, particularly when processing employee data. A data protection impact assessment (DPIA) may be required.
Who is responsible for which data? For content data (your chat inputs, uploads, knowledge vault), your company or organisation — or, if you registered directly yourself, you yourself — is the controller under the GDPR; meinGPT processes this data solely as a processor on the controller's instructions (see the data processing agreement, DPA). The controller determines the legal basis, purposes and storage period of this processing. For account, billing and security data, meinGPT is itself the controller — this notice describes our own processing in that respect.
Types of Data Processed
- Inventory data (names, company addresses, commercial register data)
- Contact details (business email, telephone numbers)
- Content data (AI chat entries, uploaded documents, API requests)
- Usage data (access times, function usage, API calls)
- Meta/communication data (IP addresses, browser information)
- Contract data (subject matter of the contract, term, licence model)
- Payment data (billing address, payment history via Stripe)
- Employee metadata (aggregated usage statistics, never content)
Data Subjects
- Administrators and main contact persons of customer companies
- End users (employees of our business customers)
- API users and developers
3. Legal Bases
The following legal bases concern the processing for which meinGPT is itself the controller (in particular account, billing and security data). For content data, the controller (your company or, on direct signup, you yourself) determines the legal basis; meinGPT processes it as a processor (see Section 4.1 and the DPA):
- Art. 6(1)(b) GDPR: Contract performance and pre-contractual enquiries
- Art. 6(1)(f) GDPR: Legitimate interests (e.g. IT security, fraud prevention)
- Art. 6(1)(a) GDPR: Consent (for optional functions)
- Art. 6(1)(c) GDPR: Legal obligations
4. Purposes of Data Processing
4.1 Provision of the Platform (processing of content data)
When you use the platform, meinGPT processes your content data (chat inputs, uploaded files, AI interactions) solely as a processor, on behalf of and on the instructions of the controller — your company or, where you registered directly, yourself.
Controller, legal basis and purposes are determined by the controller; meinGPT does not set them independently. Details are governed by the data processing agreement (DPA, Art. 28 GDPR) and, where applicable, the controller's own privacy notice.
Storage period: the provider's default retention is 12 months after last activity (chats) or after upload (documents); the controller can configure different retention and deletion rules (see Section 10). After the contract ends, the data is deleted in accordance with the DPA.
No use for training: your content is not used to train AI models (see Section 7).
4.2 User Management and Authentication
Processed data:
- Email address
- Password (encrypted)
- IP address upon login
- Session data
Purpose:
- Secure authentication
- Management of access rights
- Multi-factor authentication
Legal basis: Art. 6(1)(b) GDPR
Storage period:
- During the contract period
- 30 days after the end of the contract (waiting period)
- After that, complete deletion
4.3 Billing and Payment Processing
Processed data:
- Company data and billing address
- Contact person for invoices
- Payment history
- Credit consumption and usage volume
- Transaction data via Stripe
Purpose:
- Billing for services used
- Accounting and tax returns
- Credit checks for large customers
- Fraud prevention
Legal basis:
- Art. 6(1)(b) GDPR (performance of a contract)
- Art. 6(1)(c) GDPR (legal obligation)
- Art. 6(1)(f) GDPR (legitimate interests for fraud prevention)
Storage period: 10 years in accordance with § 147 AO and § 257 HGB
4.4 Employee Usage Analyses (B2B)
⚠️ ATTENTION Data protection risk: The processing of employee usage data is highly sensitive in terms of data protection law. Administrators must establish their own legal basis (e.g. works agreement) before activating these functions.
Processed data:
- Aggregated usage statistics (number of chats, token consumption)
- Workflow usage per department
- NO chat content or individual evaluations
- Anonymised performance indicators
Purpose:
- Licence management for corporate customers
- Departmental usage overview
- ROI analyses for AI use
Legal basis:
- Art. 6(1)(b) GDPR (contract fulfilment with companies)
- Art. 88 GDPR in conjunction with § 26 BDSG (employee data protection – responsibility of the customer)
Storage period:
- Maximum 6 months
- Automatic deletion of older data
- Only aggregated data, no individual evaluations
Data protection guarantees:
- No individual evaluations possible
- Minimum group size of 5 persons
- Opt-out option for companies
- Privacy by default: Function is deactivated by default
5. Recipients and Categories of Recipients
5.1 AI Model Providers
The AI providers used in the standard configuration process your data exclusively within the EU; your content is not used to train the models. If you, as an administrator, actively enable models or services located outside the EU/EEA within the platform, processing may take place outside the EU to that extent (see Section 6); such models are specially marked within the platform. We distinguish two levels of digital sovereignty:
Level 1 – EU-Sovereign — based in the EU with no parent company outside the EU; processing governed solely by European law:
- DeepL SE — Translation feature within the platform · EU (Germany)
- Mistral AI SAS — Operation of the Mistral models · EU (Sweden)
- GLADIA SAS — Audio transcription · EU
- DataCrunch Oy (Verda) — Operation of custom AI models · EU (Finland)
Level 2 – EU Data Residency — processing exclusively in EU data centres; also includes the EU entities of globally operating providers (parent company possibly outside the EU):
- Ubicloud B.V. — Database provider; operation of open-source AI models · EU (Germany)
- Microsoft Ireland Operations, Ltd. — Operation of the GPT and image models · EU (Sweden & France)
- OpenAI Ireland Ltd. — Operation of the GPT models with EU data residency · EU (data residency)
- Google Ireland Limited — Operation of the Gemini and Claude models · EU (Germany, Frankfurt)
- Nebius B. V. — Operation of open-source AI models · EU (Finland)
- Amazon Web Services EMEA SARL — Operation of AI models (AWS Bedrock) · EU (Frankfurt)
- TensorX Ltd. — Operation of open-source models · EU (Ireland)
- Linkup SAS — AI web search for agents · EU (France, Azure)
The always-current, complete list of our sub-processors is available in our Trust Center and — as a contractually binding annex — in your data processing agreement (DPA).
5.2 Infrastructure Service Provider
Hetzner Online GmbH (hosting, Germany)
- Purpose: Server hosting, databases, storage
- Legal basis: Art. 6(1)(b) GDPR
- Server location: Germany (Nuremberg, Falkenstein)
- ISO 27001 certified
Where this infrastructure processes content data, it does so solely as a processor on the controller's instructions (DPA); the legal basis stated above concerns the contractual relationship between you or your company and meinGPT.
5.3 Other Service Providers
For the following processing, in which we act as controller, we engage processors on the basis of agreements pursuant to Art. 28 GDPR (where a third-country element applies, safeguarded via the EU Standard Contractual Clauses or the EU-US Data Privacy Framework):
Payment Processing & Invoicing
Stripe (Stripe Payments Europe, Ltd., Dublin, Ireland; parent company USA)
- Purpose: Payment processing
- Legal basis: Art. 6(1)(b) GDPR
- Third country transfer: primarily EU; where transferred to the USA, safeguarded via SCC / DPF
Hyperline (Hyperline SAS, Paris, France)
- Purpose: Invoicing / revenue management
- Legal basis: Art. 6(1)(b) GDPR
- Processing exclusively within the EU
Customer-activated integrations (e.g. Google Workspace, Microsoft 365) are to be distinguished from the above: if an administrator activates such an integration, the Customer is itself responsible for the processing there and concludes the necessary agreements with the respective provider independently (see Section 6). Newsletters, webinars and other marketing communication are directed at website visitors and are covered in our website privacy policy.
6. Third Country Transfers
Processing by our AI providers and sub-processors takes place exclusively within the EU — there is therefore no transfer to third countries in this respect.
A third-country element can only arise from integrations you optionally activate (e.g. Microsoft 365). In those cases, any transfer is based on the EU Standard Contractual Clauses or — where applicable — the EU-US Data Privacy Framework; concluding and being responsible for your own agreements with those providers is up to you.
Despite protective measures, there is a residual risk with optional third-country integrations, as the legal situation in third countries may differ from EU standards.
7. No Use for AI Training
Important guarantee: Your data will not be used by us or our processors for training AI models. This is contractually agreed with all providers.
8. Your Rights as a Data Subject
For content data, your company (or, on direct signup, you yourself) is the controller — direct any data-subject requests to them; meinGPT assists the controller in accordance with the DPA. For account, billing and security data, for which meinGPT is the controller, you can exercise the following rights directly against us:
8.1 Right of Access (Art. 15 GDPR)
You can request information about your personal data processed by us.
8.2 Right to Rectification (Art. 16 GDPR)
You can request the rectification of inaccurate data or the completion of incomplete data.
8.3 Right to Erasure (Art. 17 GDPR)
You can request the erasure of your personal data ("right to be forgotten").
8.4 Right to Restriction of Processing (Art. 18 GDPR)
You can request the restriction of the processing of your data.
8.5 Data Portability (Art. 20 GDPR)
You have the right to receive your data in a structured, machine-readable format.
8.6 Right to Object (Art. 21 GDPR)
You may object to the processing of your data.
8.7 Right to Withdraw Consent
You may withdraw your consent at any time with effect for the future.
8.8 Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority.
How to exercise your rights:
- Self-service portal: https://app.meingpt.com/settings/privacy
- Alternatively: Email: datenschutz@heydata.eu
- Processing time: maximum 1 month
9. Cookies and Tracking
We only use technically necessary cookies:
Session cookies: To maintain your login
- Duration: Until you close your browser
- Purpose: Authentication
Preference cookies: For your settings (language, theme)
- Duration: 12 months
- Purpose: User experience
No tracking cookies: We do not use any analysis or marketing cookies.
10. Storage Periods at a Glance
Administrator-Controlled Retention (B2B)
Full control for your organisation: As a B2B platform, we enable your administrators to set retention periods themselves in accordance with your company policies, compliance requirements and business needs.
Available Retention Options
| Data Type | Admin Options | Default (if not configured) | Notes |
|---|---|---|---|
| Business Data | |||
| Chat histories & AI interactions | 30 days to unlimited | 12 months | Admin selectable by category |
| Uploaded documents | 30 days to unlimited | 12 months | Separate setting possible |
| Workflow data | 30 days to unlimited | 12 months | Dependent on business processes |
| Technical Data | |||
| API logs | 7-90 days | 30 days | For debugging & billing |
| Security logs (IP addresses) | 7-180 days | 90 days | Observe compliance requirements |
| Not Configurable | |||
| Invoice data | 10 years (legal) | - | § 147 AO, § 257 HGB |
| Contract data | 6 years after end | - | limitation periods |
| Account basic data | Contract term + 30 days | - | recovery period |
How Admin Control Works
- Global policies: Company-wide default settings
- Category-based: Different retention periods for different data types
- Department-specific: Optional different policies per department
- Compliance dashboard:
- Overview of all retention settings
- Warnings for unusually long retention periods
- Audit log of all changes
Legal Responsibility
Important for administrators: As an organisation, you are responsible for:
- Compliance with applicable data protection laws
- Setting appropriate retention periods
- Informing your employees about retention policies
- Regularly reviewing the necessity (especially for "unlimited")
Our shared responsibility model:
- Your organisation (controller): Determines the purposes and duration of data processing
- meinGPT (processor): Provides secure infrastructure and compliance tools
- Legal basis: Art. 28 GDPR – We act exclusively on your instructions
Recommendations by Industry
| Industry | Recommended Chat Retention | Justification |
|---|---|---|
| Financial services | 5–7 years | Regulatory requirements (MiFID II, etc.) |
| Healthcare | 3–10 years | Patient documentation, MDR |
| Public sector | 2-5 years | Archiving obligations |
| Tech/software | 6-18 months | Project cycles, support |
| Consulting | 2-5 years | Project documentation |
Additional Features
- ✅ Legal hold: Exclude data from deletion for legal proceedings
- ✅ Selective retention: Keep individual important chats/documents for longer
- ✅ Auto-archiving: Move older data to more cost-effective storage
- ✅ Deletion notifications: Optional 30 days before automatic deletion
- ✅ Data export: Complete export of your data at any time
Note: Employees can request the deletion of their personal data at any time, provided that there are no legal retention obligations or legitimate business interests that prevent this.
Technical Implementation of Deletion
- Immediate deletion: Upon request within 72 hours
- Automatic deletion: After expiry of the configured period
- Cascaded deletion: Including backups (max. 30 days)
- Deletion log: Proof of deletion for compliance
11. Data Security
We use extensive technical and organisational measures (TOMs):
- End-to-end encryption
- Regular security audits
- ISO 27001-compliant processes
- 24/7 monitoring
- Incident response team
Details can be found at: Technical and Organisational Measures
12. Newsletter, Webinars and Marketing Communication
Newsletters, webinar invitations and other marketing communication are directed at website visitors and prospects, not at your use of the platform. The processing of this data — including email delivery via our service provider Resend — is described in our website privacy policy.
13. API Services
Special features for API users:
- Extended logging periods for debugging (up to 30 days)
- Log rotation: Automatic deletion after 30 days
- Obligation to use in compliance with data protection
- Separate data processing agreement required
- Webhooks: Responsibility for recipient endpoints lies with the customer
14. Protection of Minors
Our B2B services are aimed exclusively at companies and their adult employees. Use by persons under the age of 18 is not permitted.
15. Changes to the Privacy Policy
We reserve the right to amend this privacy policy. The current version can always be found on our website. We will inform you by email in the event of significant changes.
16. Contact
If you have any questions about data protection, please contact:
Data Protection Officer:
heyData GmbH
Schützenstr. 5
10117 Berlin
Email: datenschutz@heydata.eu